brex
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose matches finance-platform operations, and the installer is an official npm package from the same ecosystem, so this is not overt malware. However, all Brex access and authentication are mediated through Membrane rather than direct Brex APIs, expanding trust to a third-party gateway that stores and refreshes credentials and can access sensitive financial data; combined with unpinned CLI execution, this makes the skill medium risk.
Confidence: 90%Severity: 56%
Audit Metadata